
Attackers Hijack Three Country TLDs to Forge Google Certificates
Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google

Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google

SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has

JFrog disclosed CVE-2026-105192, a CVSS 9.8 pickle deserialization flaw in LMCache that lets one network message run code. No patched

Lumen’s Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine

An FBI and Secret Service advisory says a Russian initial access broker is using stolen credentials to lock organizations out

Socket and StepSecurity say tensorlake npm version 0.5.144 carried the Shai-Hulud worm, which steals tokens and keys and punishes revoked

Federal prosecutors charged MonsterCloud owner Zohar Pinhasi with wire fraud, alleging he billed victims over $19 million while secretly paying

The State Department’s Rewards for Justice program offers up to $10 million for information on Zhang Yu, a Chinese national

An unauthorized party accessed the Georgia Power and Alabama Power customer portal, exposing about 400,000 accounts, including partial SSNs and

Google released Chrome 155 with fixes for 247 vulnerabilities, four of them critical use-after-free flaws. Google reports no in-the-wild exploitation.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.